The overall risk/impact is MEDIUM and affects version ranges not explicitly stated in the article. (CVSS 6.5 — Medium): An authenticated arbitrary file write vulnerability exists via Content-Disposition path traversal in SimpleHttp offline-download tool.
An attacker can traverse out of the temp directory to write any file the alist process can write, requiring a non-admin user with PermAddOfflineDownload permission on any path. (GHSA-x4q4-7phh-42j9, fsmanage/fsbatch path traversal patched in v3.57.0).[/subscribe_to_unlock_form]
The overall risk/impact is MEDIUM and affects version ranges not explicitly stated in the article. (CVSS 6.5 — Medium): An authenticated arbitrary file write vulnerability exists via Content-Disposition path traversal in SimpleHttp offline-download tool.
An attacker can traverse out of the temp directory to write any file the alist process can write, requiring a non-admin user with PermAddOfflineDownload permission on any path. (GHSA-x4q4-7phh-42j9, fsmanage/fsbatch path traversal patched in v3.57.0).[emaillocker id="1283"]
The offline-download `SimpleHttp` downloader was not in scope of that fix; the vulnerable code is on `main` HEAD as of the time of this report (verified against the openlistteam/openlist tree's.
We recommend you to update github.com/OpenListTeam/OpenList to version 4.2.3.
| Tactic | Technique Id | Technique | Sub-technique |
|---|---|---|---|
| Initial access | T1190 | Exploit Public | Facing Application- |
| Persistence | T1547.001 | Boot or Logon Autostart Execution | Registry Run Keys / Startup Folder |
| Defence Evasion | T1027.002 | Obfuscated Files or Information | Software Packing |
| Defence Evasion | T1036.005 | Masquerading | Match Legitimate Resource Name or Location |
The following reports contain further technical details:
[/emaillocker]